Security

Success Story: Cisco Security Agent Helps Columbus State University Combat Evolving Security Attacks
Network security tools: Cisco Security Agent provides threat protection for server and desktop computing systems. Read more about Cisco's Security Agent intrusion prevention system and intrusion detection system software solutions.

from Cisco Systems Inc.

Background
Columbus State University (CSU) is a four-year higher educational institution located in Columbus, Georgia. Since its founding in 1958, CSU has evolved into a flourishing state university offering graduate and undergraduate programs, some of which have achieved national reputations. The university provides cultural enrichment, educational opportunities, and economic development assistance to the citizens, businesses, and industries located in the region. Every dollar spent by CSU generates an additional 56 cents for the local economy, and CSU has a US$146 million annual impact on the regional and state economies.

As of early 2002, the Columbus State University network had luckily escaped any major attacks or security breaches. At that time, the incoming and outgoing network traffic at CSU was minimally filtered, and the university's servers and desktops were protected only by the weekly manual application of security patches and software updates.

Periodic implementation of hotfixes, patches, and software updates is a valid security measure, however, this measure can really only mitigate the risks associated with "known" attack methods—those with which the security industry has already had experience. Relying solely on patches and updates for security leaves the network vulnerable to new attacks and the IT administrators one step behind the hackers.

Challenge
In August of 2002, CSU experienced its first major attack. The security breach was an exploit of an extended procedure function buffer overflow of Microsoft SQL 7 and compromised three of CSU's critical servers. The CSU IT team had to rebuild the compromised servers that handled such crucial functions as the help desk system and event scheduling system. According to Senior System Support Specialist Mack Ragan, "For that period of time, the very efficient way of handling help desk inquiries and event scheduling was gone, and we had to go back to using inefficient processes. This led to much more time being spent by the people who were in charge of those functions."

Ragan and his colleague dedicated many hours to rebuilding the servers. The rest of their responsibilities fell by the wayside during that time. Ragan was determined not to let this type of incident happen again. "These attacks were the first major security breaches that the university had ever experienced. It took hours of staff time to get the network up and running again. It was clear that the University could not afford to deal with another attack of this magnitude," he explains.

Ragan recognized that while important, hotfixes, and patches couldn't offer sufficient protection. He says, "Whether we installed [the patches] properly or not, it did not matter because we got hacked into and our servers were down."

If you're interested in this topic, these articles may be helpful:

Cisco SMB-Class Security Solutions: Technical and Business Advantages of Cisco Security Solutions
The Protected Workplace Introduction Networks and the Internet are...
Top Five Security Issues for Small and Medium-Sized Businesses
from Cisco Systems Inc. Summary Small and medium-sized businesses ...
Core Elements of the Cisco Self-Defending Network Strategy
from Cisco Systems Inc. Thanks in part to a Cisco® advertising ...
South Bay BMW Achieves Unmatched Availability and Security with its Cisco Network
from Cisco Systems Inc. South Bay BMW needed to guard its network a...
Protect Your Business
As viruses, worms, and hackers continue to plague business-technology ...

Related Jobs:

Sr. Oracle Database Administrator #ODBA-1106 - MO - Kansas City - SunGard
Reference No.: ODBA-1106 Opening Date: November 4, 2005 Job Title:...
Technologist #143807 - WA - Redmond - Microsoft Corporation
Are you passionate about security? Are you a veteran in the art of hun...
Network Engineer #147453 - WA - Redmond - Microsoft Corporation
Senior Security Engineer Come join our security team! We’re looking...
System Architect #S05-0121 - NY - Syracuse - Excellus Blue Cross Blue Shield
Title: System Architect Department: Security Services Operating Te...
Production DB2 DBA #DBA003 - IL - Hinsdale - SunGard
Reference No.: DBA003 Opening Date: January 11, 2006 Job Title: Pr...
SQL DBA Analyst #647 - TX - Houston - RCG Information Technology
Description: All applicants must have a minimum of 3 years IT Industry...
Network Administrator #892 - VA - Springfield - Management Systems Designers, Inc.
Provide network and architecture, administration, support and load bal...
Security Assurance Analyst #X0500114 - ON - Ottawa - Entrust Inc
Security Assurance Analyst Ref. Number: X0500114 Category: Softwa...
Sr. Security Analyst/IDS & Forensic #05-2885 SD - PA - Philadelphia - SunGard
Reference No.: 05-2885 SD Opening Date: October 20, 2005 Job Title...
Senior Information Security Analyst #4081 - WI - Kenosha - Snap-on Incorporated
Senior Information Security Analyst Company: Snap-on Incorporated ...